Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:2613-1

Опубликовано: 24 июн. 2026
Источник: suse-cvrf

Описание

Security update for xen

This update for xen fixes the following issues

  • CVE-2025-54518: AMD-SN-7052: CPU OP Cache Corruption (bsc#1264066).
  • CVE-2026-42487: x86 HVM I/O port list traversal (bsc#1266952).
  • CVE-2026-42488: x86: mismatched mapcache metadata (bsc#1266955).
  • CVE-2026-42489,CVE-2026-42490: domctl lock open to abuse (bsc#1266953).

Список пакетов

Image SLES15-SP4-BYOS
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-Azure
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-EC2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-GCE
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-CHOST-BYOS
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-CHOST-BYOS-Aliyun
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-CHOST-BYOS-Azure
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-CHOST-BYOS-EC2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-CHOST-BYOS-GCE
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-CHOST-BYOS-SAP-CCloud
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-HPC-BYOS
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-HPC-BYOS-Azure
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-HPC-BYOS-EC2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-HPC-BYOS-GCE
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-HPC-EC2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-HPC-GCE
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-Hardened-BYOS
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-Hardened-BYOS-Azure
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-Hardened-BYOS-EC2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-Hardened-BYOS-GCE
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-Azure
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-BYOS
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-BYOS-Azure
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-BYOS-EC2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-BYOS-GCE
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-EC2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-GCE
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-Hardened
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-Hardened-Azure
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-Hardened-BYOS
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-Hardened-BYOS-Azure
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-Hardened-BYOS-EC2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-Hardened-BYOS-GCE
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAP-Hardened-GCE
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAPCAL
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAPCAL-Azure
xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAPCAL-EC2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-SAPCAL-GCE
xen-libs-4.16.7_10-150400.4.86.2
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
xen-4.16.7_10-150400.4.86.2
xen-devel-4.16.7_10-150400.4.86.2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
xen-tools-xendomains-wait-disk-4.16.7_10-150400.4.86.2
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
xen-4.16.7_10-150400.4.86.2
xen-devel-4.16.7_10-150400.4.86.2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
xen-tools-xendomains-wait-disk-4.16.7_10-150400.4.86.2
SUSE Linux Enterprise Micro 5.3
xen-libs-4.16.7_10-150400.4.86.2
SUSE Linux Enterprise Micro 5.4
xen-libs-4.16.7_10-150400.4.86.2
SUSE Linux Enterprise Server 15 SP4-LTSS
xen-4.16.7_10-150400.4.86.2
xen-devel-4.16.7_10-150400.4.86.2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
xen-tools-xendomains-wait-disk-4.16.7_10-150400.4.86.2
SUSE Linux Enterprise Server for SAP Applications 15 SP4
xen-4.16.7_10-150400.4.86.2
xen-devel-4.16.7_10-150400.4.86.2
xen-libs-4.16.7_10-150400.4.86.2
xen-tools-4.16.7_10-150400.4.86.2
xen-tools-domU-4.16.7_10-150400.4.86.2
xen-tools-xendomains-wait-disk-4.16.7_10-150400.4.86.2

Описание

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.


Затронутые продукты
Image SLES15-SP4-BYOS-Azure:xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-EC2:xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-EC2:xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-GCE:xen-libs-4.16.7_10-150400.4.86.2

Ссылки

Описание

HVM guest I/O port accesses are subject to either emulation or at least translation. Translations are managed by the device model (via XEN_DOMCTL_ioport_mapping), and hence the linked list used may changed at any time. Traversal of those lists (while handling guest I/O port accesses) therefore needs synchronizing with updates, which was missing so far.


Затронутые продукты
Image SLES15-SP4-BYOS-Azure:xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-EC2:xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-EC2:xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-GCE:xen-libs-4.16.7_10-150400.4.86.2

Ссылки

Описание

Some shadow paging errors paths will switch the page-tables without updating the currently running vCPU reference. This causes a mismatch between the loaded page-tables and the mapcache metadata which can lead to corruption of the mapcache.


Затронутые продукты
Image SLES15-SP4-BYOS-Azure:xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-EC2:xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-EC2:xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-GCE:xen-libs-4.16.7_10-150400.4.86.2

Ссылки

Описание

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or by a domain controlling a particular guest. Some of these operations may not be executed in parallel, so a system-wide lock is used. The way that lock is acquired is, however, not providing any fairness. This is CVE-2026-42489. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. This is CVE-2026-42490.


Затронутые продукты
Image SLES15-SP4-BYOS-Azure:xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-EC2:xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-EC2:xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-GCE:xen-libs-4.16.7_10-150400.4.86.2

Ссылки

Описание

[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] To create and manage guests, domctl operations are used by the control domain, a possible Xenstore domain, or by a domain controlling a particular guest. Some of these operations may not be executed in parallel, so a system-wide lock is used. The way that lock is acquired is, however, not providing any fairness. This is CVE-2026-42489. Furthermore, with XSM/Flask in use, the lock acquire will, for some operations, occur ahead of any permission checking. This is CVE-2026-42490.


Затронутые продукты
Image SLES15-SP4-BYOS-Azure:xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-EC2:xen-libs-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-EC2:xen-tools-domU-4.16.7_10-150400.4.86.2
Image SLES15-SP4-BYOS-GCE:xen-libs-4.16.7_10-150400.4.86.2

Ссылки